Arbitrary file upload in Tenable Nessus - CVE-2023-6062

 

Arbitrary file upload in Tenable Nessus - CVE-2023-6062

Published: November 20, 2023


Vulnerability identifier: #VU83307
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-6062
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of file during file upload. A remote user with administrative privileges can alter Nessus Rules variables and overwrite arbitrary files on the remote host, leading to denial of service.


Affected software

Tenable Nessus

How to mitigate CVE-2023-6062

Install updates from vendor's website.

Tenable Nessus - addressed in versions 10.5.7, 10.6.3

External References

Related Security Bulletins